CVE-2026-16367

CRITICAL

Sandbox escape due to invalid pointer in the Disability Access APIs component

Title source: cna
STIX 2.1

Description

Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Scores

CVSS v3 10.0
EPSS 0.0037
EPSS Percentile 30.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-119 CWE-416 CWE-787
Status published
Products (4)
mozilla/firefox < 153.0.0
Mozilla/Firefox 153
mozilla/thunderbird < 153.0
Mozilla/Thunderbird 153
Published Jul 21, 2026
Tracked Since Jul 21, 2026